 鲜花( 1)  鸡蛋( 0)
|

楼主 |
发表于 2006-5-5 16:59
|
显示全部楼层
Logfile of HijackThis v1.99.1
. ?/ y. k% \0 s% O5 V; ZScan saved at 16:55:24, on 2006-5-6
0 ~, H0 C- U9 T/ Q0 \Platform: Windows XP SP2 (WinNT 5.01.2600)
' S! \5 f5 r/ N; o7 uMSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
! y" ~: W2 j! m1 N. V) K1 P
- U; ^6 Q+ a3 mRunning processes: S" s. k/ a$ P. {/ E
C:\WINDOWS\System32\smss.exe
5 J% a, B4 Z7 D) a$ g2 yC:\WINDOWS\system32\winlogon.exe7 r/ `8 |, T$ p3 T3 t, w. b4 S# u
C:\WINDOWS\system32\services.exe
' U$ K2 z+ n% Z) J& m5 j; QC:\WINDOWS\system32\lsass.exe
* E& i7 X7 S: m. z1 V, SC:\Program Files\Common Files\Virtual Token\vtserver.exe( G# B' _6 T# S7 W
C:\WINDOWS\system32\ibmpmsvc.exe: E. z0 n! @8 e6 m7 H
C:\WINDOWS\system32\svchost.exe/ o, \* [* K2 w, n7 N
C:\WINDOWS\System32\svchost.exe- i' U% a) u$ W" H) ^
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe6 Y5 F- j# e4 K' t% Q- Q
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
( L; j: Z. }. y8 y. T* u7 q4 m8 OC:\WINDOWS\system32\spoolsv.exe
; E2 L7 x D9 C# a* F( qC:\PROGRA~1\F-Secure\BackWeb\7681197\Program\SERVIC~1.EXE8 F a. f% Q( G& w: ?( X
C:\Program Files\F-Secure\Anti-Virus\fsgk32st.exe
# z! }6 [: B+ J( b+ j5 i; hC:\Program Files\F-Secure\BackWeb\7681197\program\fsbwsys.exe
/ G) ^# x, z' |+ |' V5 FC:\Program Files\F-Secure\Anti-Virus\FSGK32.EXE
0 J9 e7 w! R. ?! XC:\Program Files\F-Secure\Common\FSMA32.EXE5 b: g+ F0 H' Z$ n7 F8 }
C:\Program Files\F-Secure\Common\FSMB32.EXE3 p& ]6 \; @9 t$ c+ ~ T
C:\Program Files\IBM\IBM Rapid Restore Ultra\rrpcsb.exe
7 f) f' D2 C% c ?1 H. nC:\Program Files\F-Secure\Anti-Virus\fssm32.exe& K! P9 J, n8 A a2 R7 Z
C:\WINDOWS\System32\QCONSVC.EXE
. f. a. C0 E. L; y8 j/ }1 ]3 M% _) K1 |C:\Program Files\F-Secure\Common\FCH32.EXE+ D+ O! ?3 H5 \$ k
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
' A2 D3 B+ X# x) {$ y; WC:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
0 p: s; t; V& B' s. c3 h; ~C:\WINDOWS\System32\TPHDEXLG.EXE
/ G& j, [' y8 J- W; C/ t1 d! L# x" ^C:\Program Files\F-Secure\Common\FAMEH32.EXE0 X9 F* C2 J, j; [/ c0 u
C:\WINDOWS\system32\TpKmpSVC.exe
/ q2 e: b/ j8 D3 J: N, H# wC:\Program Files\F-Secure\Anti-Virus\fsqh.exe
0 u! W) [/ Q* _) D$ X fC:\Program Files\F-Secure\Anti-Virus\fsrw.exe
3 K4 U( A4 H+ m% J1 X7 rC:\Program Files\F-Secure\Common\FNRB32.EXE
7 v" `- `" ^3 O- \, XC:\Program Files\F-Secure\FWES\Program\fsdfwd.exe
! s3 T: s+ V& W' h% a2 qC:\Program Files\F-Secure\Common\FIH32.EXE5 h- q: i. [3 u6 d! u
C:\Program Files\F-Secure\Anti-Virus\fsav32.exe
( s/ O$ i- i" L+ h' s/ a' lC:\WINDOWS\Explorer.EXE
, @5 q) F, c8 r7 G' }/ I- o3 [$ sC:\Program Files\Synaptics\SynTP\SynTPLpr.exe
& y; a6 `, s5 ]5 g* P) D$ t6 }C:\Program Files\Synaptics\SynTP\SynTPEnh.exe! K, o- u* p8 M# @- k+ a* K/ m# d
C:\WINDOWS\system32\hkcmd.exe
8 D9 l3 d" ?6 g, a' b$ ^C:\WINDOWS\system32\TpShocks.exe9 U. m+ U- j9 a# C* N! I A
C:\PROGRA~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe( `! I7 b9 W D, @3 j3 X I
C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe7 f' G: ^9 j# ?& |8 U
C:\Program Files\ThinkPad\PkgMgr\HOTKEY\TPONSCR.exe
2 m8 r" X+ H5 e& a# rC:\Program Files\ThinkPad\PkgMgr\HOTKEY_1\TpScrex.exe9 u l' q0 c2 c" \
C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
( {. Q$ U- w9 v1 dC:\WINDOWS\system32\dla\tfswctrl.exe' m, w" D" G. `0 A4 ?8 ~
C:\Program Files\IBM\Messages By IBM\ibmmessages.exe' h/ J0 d/ R1 v1 Q1 M
C:\IBMTOOLS\UTILS\ibmprc.exe4 X! R8 \4 L4 E7 x! O/ q
C:\Program Files\ThinkPad\ConnectUtilities\QCTRAY.EXE
% O1 M+ Y, l d1 A6 OC:\Program Files\ThinkPad\ConnectUtilities\QCWLICON.EXE
' _) D- |, l* I! z* eC:\WINDOWS\System32\svchost.exe- D8 e% d3 M! I" @
C:\WINDOWS\system32\rundll32.exe$ g6 S/ }5 ~) k
C:\Program Files\F-Secure\Common\FSM32.EXE
2 {0 f7 j1 @, S7 ` Q) m+ v. H AC:\WINDOWS\system32\CTFMON.EXE9 v& u0 b) [/ A5 E! s3 x' m
C:\PROGRA~1\F-Secure\ANTI-S~1\fsaw.exe; U1 q/ |' @- U* D2 C9 r
C:\Program Files\Digital Line Detect\DLG.exe
# _: H) f. r9 p+ \& N# RC:\Program Files\F-Secure\BackWeb\7681197\program\F-Secure Automatic Update.exe
9 ?7 y2 s1 m) g* U! CC:\Program Files\F-Secure\FSGUI\fsguidll.exe7 ^. f4 X; Y- S5 [$ x
C:\Program Files\Messenger\msmsgs.exe
& t0 p7 e4 K8 V4 LC:\Program Files\Internet Explorer\iexplore.exe
4 t6 f" u/ x% l$ sC:\DOCUME~1\SHIXIN~1\LOCALS~1\Temp\Temporary Directory 1 for hijackthis[1].zip\HijackThis.exe9 K. E4 x8 w4 `! i3 ]+ d
. |" _$ [: S4 N# I+ w9 M* D' Z
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
7 s X6 p( n$ b z% MO4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
- V* {$ \* f8 @ gO4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe9 W) s6 o M: G( D4 q
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe, ~6 r" q' o8 A g. R) s/ Q
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
0 S; P* U. h+ t9 l0 H: nO4 - HKLM\..\Run: [TPKMAPHELPER] C:\Program Files\ThinkPad\Utilities\TpKmapAp.exe -helper
! |4 s0 S! @# EO4 - HKLM\..\Run: [TpShocks] TpShocks.exe
2 t. Z' [( L1 eO4 - HKLM\..\Run: [TPHOTKEY] C:\PROGRA~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe
' B+ o' Q. t5 {9 V% y( r7 hO4 - HKLM\..\Run: [ControlCenter] "C:\Program Files\IBM fingerprint software\ctlcntr.exe" /startup4 P- T4 J9 ], h4 C
O4 - HKLM\..\Run: [TP4EX] tp4ex.exe7 V9 G6 v3 h' i
O4 - HKLM\..\Run: [EZEJMNAP] C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe
5 M9 l$ I7 {/ a- H3 D* t# \7 uO4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe4 s2 e: a$ h- E5 V8 D
O4 - HKLM\..\Run: [SoundMAX] C:\Program Files\Analog Devices\SoundMAX\Smax4.exe /tray# o. N& ]3 `& [9 w5 L% A
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r, O K! Q2 q' }* K
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
3 g7 g# G: E# F6 oO4 - HKLM\..\Run: [ibmmessages] C:\Program Files\IBM\Messages By IBM\\ibmmessages.exe' @1 r" t3 W" Q1 E* D" U4 F
O4 - HKLM\..\Run: [IBMPRC] C:\IBMTOOLS\UTILS\ibmprc.exe
- y( {# C+ q( I% J4 S4 NO4 - HKLM\..\Run: [QCTRAY] C:\Program Files\ThinkPad\ConnectUtilities\QCTRAY.EXE+ a/ M& a" _8 k+ n8 L8 m7 ~, g& i
O4 - HKLM\..\Run: [QCWLICON] C:\Program Files\ThinkPad\ConnectUtilities\QCWLICON.EXE1 o9 Q/ X; Z# S# A+ d
O4 - HKLM\..\Run: [PWRMGRTR] rundll32 C:\PROGRA~1\ThinkPad\UTILIT~1\PWRMGRTR.DLL,PwrMgrBkGndMonitor# |) f: q- x& _( n4 V9 E% x [ e9 x
O4 - HKLM\..\Run: [BLOG] rundll32 C:\PROGRA~1\ThinkPad\UTILIT~1\BatLogEx.DLL,StartBattLog' Z1 d: }; p" Y. d& R! H7 [, }$ R
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
) y6 G8 s0 \1 Z6 A: P2 [7 LO4 - HKLM\..\Run: [IMEKRMIG6.1] C:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE
. {+ N' b& n3 e2 b1 ^O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC: [' l. _4 |1 B c! V
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC+ L- Q3 O3 j C6 h6 ?% ?. Q
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
8 r$ Z/ s0 K6 I) v& @& g) x* N; K0 W3 VO4 - HKLM\..\Run: [F-Secure Manager] "C:\Program Files\F-Secure\Common\FSM32.EXE" /splash
. ?/ C* z2 u2 u/ Y2 s7 d3 gO4 - HKLM\..\Run: [F-Secure TNB] "C:\Program Files\F-Secure\TNB\TNBUtil.exe" /CHECKALL /WAITFORSW/ `% B/ D, @5 a h
O4 - HKCU\..\Run: [ibmmessages] C:\Program Files\IBM\Messages By IBM\ibmmessages.exe
8 O: N. [% g9 z- W6 |' y5 QO4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe" C" S4 @0 N3 o! k w3 l: s9 j
O4 - Global Startup: Digital Line Detect.lnk = ?+ ~$ g" N, r- H, h |
O4 - Global Startup: F-Secure Automatic Update.lnk = C:\Program Files\F-Secure\BackWeb\7681197\program\F-Secure Automatic Update.exe
) z5 D: K' d6 H. s, l7 t; N! ZO8 - Extra context menu item: &Block this popup - C:\Program Files\F-Secure\Anti-Spyware\blockpopups.htm
& C/ }5 y, o( k8 W# qO9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\IBM\Java142\jre\bin\NPJPI142.dll
0 m T+ `% a' j* t- JO9 - Extra 'Tools' menuitem: IBM Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\IBM\Java142\jre\bin\NPJPI142.dll( @, L- o' ?: k3 Q- b" {" a
O9 - Extra button: IE Shield - {300DB664-75B5-47c0-8B45-A44ACCF73C00} - C:\Program Files\F-Secure\Anti-Spyware\ieshield.dll
8 x) w1 O6 h5 Q1 H$ M% z+ dO9 - Extra 'Tools' menuitem: IE Shield... - {300DB664-75B5-47c0-8B45-A44ACCF73C00} - C:\Program Files\F-Secure\Anti-Spyware\ieshield.dll
) e( B6 Z c7 {, |( z6 p$ W& PO9 - Extra button: Software Installer - {D1A4DEBD-C2EE-449f-B9FB-E8409F9A0BC5} - C:\Program Files\Lenovo\PkgMgr\\PkgMgr.exe
$ D4 M5 N) P9 Q; R# KO9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe2 V% O3 F2 F. V0 t2 A# u- T
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe7 U3 Q. f6 `0 `
O10 - Unknown file in Winsock LSP: c:\program files\f-secure\fsps\program\fslsp.dll2 R6 B: C) d; j
O10 - Unknown file in Winsock LSP: c:\program files\f-secure\fsps\program\fslsp.dll
' }! N5 r7 e/ n# a1 `4 uO10 - Unknown file in Winsock LSP: c:\program files\f-secure\fsps\program\fslsp.dll
" r; I( R2 ]& CO11 - Options group: [JAVA_IBM] Java (IBM)
4 G e; H$ D9 U4 n8 o' r( Y, {* zO20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll; o& Q8 j4 p9 _* l9 J; n0 B2 C2 ^
O20 - Winlogon Notify: psfus - C:\Program Files\IBM fingerprint software\psfus.dll j8 k# h9 N, |& M. M! w
O20 - Winlogon Notify: QConGina - C:\WINDOWS\SYSTEM32\QConGina.dll
5 m, i% ]) R0 RO20 - Winlogon Notify: tphotkey - C:\WINDOWS\SYSTEM32\tphklock.dll2 {0 a$ b9 q/ K, A8 K
O23 - Service: F-Secure Automatic Update (BackWeb Plug-in - 7681197) - F-Secure Automatic Update - C:\PROGRA~1\F-Secure\BackWeb\7681197\Program\SERVIC~1.EXE
& F; |5 V" N; c0 jO23 - Service: EvtEng - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe% j5 Z" Q& v& I0 B4 M% |1 v) Q( U+ V E
O23 - Service: FSGKHS (F-Secure Gatekeeper Handler Starter) - F-Secure Corp. - C:\Program Files\F-Secure\Anti-Virus\fsgk32st.exe
3 z' I. }/ h" ~/ C: d9 v# QO23 - Service: F-Secure Network Request Broker - F-Secure Corporation - C:\Program Files\F-Secure\Common\FNRB32.EXE
# V3 q3 w! l9 q5 y' A8 Z8 B. qO23 - Service: fsbwsys - F-Secure Corp. - C:\Program Files\F-Secure\BackWeb\7681197\program\fsbwsys.exe
. J; a" K; P E" r; t0 X+ oO23 - Service: F-Secure Anti-Virus Firewall Daemon (FSDFWD) - F-Secure Corporation - C:\Program Files\F-Secure\FWES\Program\fsdfwd.exe
8 X5 w. h: F% ?# L! L# f! jO23 - Service: F-Secure Management Agent (FSMA) - F-Secure Corporation - C:\Program Files\F-Secure\Common\FSMA32.EXE
8 T' a* O4 f2 I! `( D( g* a8 {O23 - Service: IBM Rapid Restore Ultra Service - Unknown owner - C:\Program Files\IBM\IBM Rapid Restore Ultra\rrpcsb.exe
% J+ j( F) z8 R" zO23 - Service: IBM PM Service (IBMPMSVC) - Unknown owner - C:\WINDOWS\system32\ibmpmsvc.exe: T/ W5 ~1 k, h
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
. x. ~' R! w; d- h* `9 fO23 - Service: IBM PSA Access Driver Control (PsaSrv) - Unknown owner - C:\WINDOWS\system32\PsaSrv.exe (file missing)
9 Q* r! T! E3 P) i$ zO23 - Service: QCONSVC - IBM Corp. - C:\WINDOWS\System32\QCONSVC.EXE
) @" k, U+ ^; o1 lO23 - Service: RegSrvc - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
+ _2 ^) q: c4 [, t/ MO23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
4 o4 I- E. H' S2 o( C5 yO23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
, j3 P9 b" q/ v; a, S0 IO23 - Service: IBM HDD APS Logging Service (TPHDEXLGSVC) - IBM Corporation - C:\WINDOWS\System32\TPHDEXLG.EXE
$ v. x4 |, l* X5 c4 ]O23 - Service: IBM KCU Service (TpKmpSVC) - Unknown owner - C:\WINDOWS\system32\TpKmpSVC.exe+ ~2 ]4 L1 M% D1 L( ~2 R& o
O23 - Service: Protector Suite Virtual Token (vtserver) - UPEK Inc. - C:\Program Files\Common Files\Virtual Token\vtserver.exe |
|